CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability
BID:10384
Info
CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability
| Bugtraq ID: | 10384 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0396 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | This issue was discovered by Stefan Esser <[email protected]>. |
| Vulnerable: |
NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 NetBSD NetBSD Current Gentoo Linux 1.4 CVS CVS 1.12.7 CVS CVS 1.12.5 CVS CVS 1.12.2 CVS CVS 1.12.1 CVS CVS 1.11.15 CVS CVS 1.11.14 CVS CVS 1.11.11 CVS CVS 1.11.10 CVS CVS 1.11.6 CVS CVS 1.11.5 CVS CVS 1.11.4 CVS CVS 1.11.3 CVS CVS 1.11.2 CVS CVS 1.11.1 p1 CVS CVS 1.11.1 CVS CVS 1.11 CVS CVS 1.10.8 CVS CVS 1.10.7 |
| Not Vulnerable: |
CVS CVS 1.12.8 CVS CVS 1.11.16 |
Discussion
CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability
CVS is prone to a remote heap overflow vulnerability. This issue presents itself during the handling of user-supplied input for entry lines with 'modified' and 'unchanged' flags. This vulnerability can allow an attacker to overflow a vulnerable buffer on the heap, possibly leading to arbitrary code execution.
CVS versions 1.11.15 and prior and CVS feature versions 1.12.7 and prior are prone to this issue.
**UPDATE: Symantec has confirmed that this vulnerability is being actively exploited in the wild. Administrators are urged to upgrade and block external access to potentially vulnerable servers, if possible.
CVS is prone to a remote heap overflow vulnerability. This issue presents itself during the handling of user-supplied input for entry lines with 'modified' and 'unchanged' flags. This vulnerability can allow an attacker to overflow a vulnerable buffer on the heap, possibly leading to arbitrary code execution.
CVS versions 1.11.15 and prior and CVS feature versions 1.12.7 and prior are prone to this issue.
**UPDATE: Symantec has confirmed that this vulnerability is being actively exploited in the wild. Administrators are urged to upgrade and block external access to potentially vulnerable servers, if possible.
Exploit / POC
CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
Symantec has confirmed successful exploitation of this vulnerability in the wild. The following exploit code has been published:
CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.
Symantec has confirmed successful exploitation of this vulnerability in the wild. The following exploit code has been published:
Solution / Fix
CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability
Solution:
Debian has released an advisory DSA 505-1 to address this issue. Please see the referenced advisory for more information.
SuSE has released an advisory SuSE-SA:2004:013 to address this issue. Please see the referenced advisory for more information.
A FreeBSD advisory (FreeBSD-SA-04:10.cvs) is available that includes information about how to address this issue. Please see the attached advisory for further information.
OpenPKG has released advisory OpenPKG-SA-2004.022 that adresses this issue. Please see the attached advisory for further information.
Mandrake Linux has released advisory MDKSA-2004:048 and fixes dealing with this issue. Please see the referenced advisory for more information.
RedHat has released advisory FEDORA-2004-126 to provide fixes for Fedora Core 1. Please see the attached advisory for details on obtaining and applying fixes.
RedHat has released advisory FEDORA-2004-131 to provide fixes for Fedora Core 2. Please see the attached advisory for details on obtaining and applying fixes.
RedHat has released advisory RHSA-2004:190-14 to provide fixes for this issue. Please see the attached advisory in web references for details on obtaining and applying fixes.
A Slackware advisory (SSA:2004-140-01) is available that provides updates for this issue. Please see the attached advisory for further details.
Gentoo has released advisory GLSA 200405-12 to provide fixes for this issue. Please see the attached advisory for further details. It is recommended that affected users issue the following commands as superuser:
emerge sync
emerge -pv ">=dev-util/cvs-1.11.16"
emerge ">=dev-util/cvs-1.11.16"
OpenBSD has released patches to resolve this issue in versions 3.4 and 3.5. Please see the patch files themselves for instructions on applying them to your system. Please see the referenced announcement from Otto Moerbeek for more information.
CVS versions 1.11.16 and 1.12.8 have been released to address this issue.
Turbolinux has released advisory TLSA-2004-15 to provide fixes for this issue. Please see the attached advisory for further details.
Silicon Graphics has released advisory 20040508-01-U and fixes dealing with this and other issues for SGI ProPack 2.4. Please see the referenced advisory for more information.
NetBSD has released advisory 2004-008 addressing this issue. Please see the referenced advisory for further information:
Red Hat Fedora Legacy advisory FLSA-2004:1620 has been released dealing with this and other issues for Red Hat 7.3 and 9.0. Please see the referenced advisory for more information.
An Immunix Linux upgrade has been made available.
CVS CVS 1.10.7
CVS CVS 1.10.8
CVS CVS 1.11
CVS CVS 1.11.1 p1
CVS CVS 1.11.1
CVS CVS 1.11.10
CVS CVS 1.11.11
CVS CVS 1.11.14
CVS CVS 1.11.15
CVS CVS 1.11.2
CVS CVS 1.11.3
CVS CVS 1.11.4
CVS CVS 1.11.5
CVS CVS 1.11.6
CVS CVS 1.12.1
CVS CVS 1.12.2
CVS CVS 1.12.5
CVS CVS 1.12.7
Solution:
Debian has released an advisory DSA 505-1 to address this issue. Please see the referenced advisory for more information.
SuSE has released an advisory SuSE-SA:2004:013 to address this issue. Please see the referenced advisory for more information.
A FreeBSD advisory (FreeBSD-SA-04:10.cvs) is available that includes information about how to address this issue. Please see the attached advisory for further information.
OpenPKG has released advisory OpenPKG-SA-2004.022 that adresses this issue. Please see the attached advisory for further information.
Mandrake Linux has released advisory MDKSA-2004:048 and fixes dealing with this issue. Please see the referenced advisory for more information.
RedHat has released advisory FEDORA-2004-126 to provide fixes for Fedora Core 1. Please see the attached advisory for details on obtaining and applying fixes.
RedHat has released advisory FEDORA-2004-131 to provide fixes for Fedora Core 2. Please see the attached advisory for details on obtaining and applying fixes.
RedHat has released advisory RHSA-2004:190-14 to provide fixes for this issue. Please see the attached advisory in web references for details on obtaining and applying fixes.
A Slackware advisory (SSA:2004-140-01) is available that provides updates for this issue. Please see the attached advisory for further details.
Gentoo has released advisory GLSA 200405-12 to provide fixes for this issue. Please see the attached advisory for further details. It is recommended that affected users issue the following commands as superuser:
emerge sync
emerge -pv ">=dev-util/cvs-1.11.16"
emerge ">=dev-util/cvs-1.11.16"
OpenBSD has released patches to resolve this issue in versions 3.4 and 3.5. Please see the patch files themselves for instructions on applying them to your system. Please see the referenced announcement from Otto Moerbeek for more information.
CVS versions 1.11.16 and 1.12.8 have been released to address this issue.
Turbolinux has released advisory TLSA-2004-15 to provide fixes for this issue. Please see the attached advisory for further details.
Silicon Graphics has released advisory 20040508-01-U and fixes dealing with this and other issues for SGI ProPack 2.4. Please see the referenced advisory for more information.
NetBSD has released advisory 2004-008 addressing this issue. Please see the referenced advisory for further information:
Red Hat Fedora Legacy advisory FLSA-2004:1620 has been released dealing with this and other issues for Red Hat 7.3 and 9.0. Please see the referenced advisory for more information.
An Immunix Linux upgrade has been made available.
CVS CVS 1.10.7
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.10.8
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.1 p1
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489 -
Debian cvs_1.11.1p1debian-9woody4_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_alpha.deb -
Debian cvs_1.11.1p1debian-9woody4_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_arm.deb -
Debian cvs_1.11.1p1debian-9woody4_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_hppa.deb -
Debian cvs_1.11.1p1debian-9woody4_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_i386.deb -
Debian cvs_1.11.1p1debian-9woody4_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_ia64.deb -
Debian cvs_1.11.1p1debian-9woody4_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_m68k.deb -
Debian cvs_1.11.1p1debian-9woody4_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_mips.deb -
Debian cvs_1.11.1p1debian-9woody4_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_mipsel.deb -
Debian cvs_1.11.1p1debian-9woody4_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_powerpc.deb -
Debian cvs_1.11.1p1debian-9woody4_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_s390.deb -
Debian cvs_1.11.1p1debian-9woody4_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/c/cvs/cvs_1.11.1p1debian- 9woody4_sparc.deb -
OpenBSD 007_cvs2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/007_cvs2.patch -
OpenBSD 021_cvs2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/021_cvs2.patch -
RedHat cvs-1.11.1p1-14.legacy.3.i386.rpm
http://download.fedoralegacy.org/redhat/7.3/updates/i386/cvs-1.11.1p1- 14.legacy.3.i386.rpm -
SuSE cvs-1.11.1p1-329.i386.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/d3/cvs-1.11.1p1-329.i386.p atch.rpm -
SuSE cvs-1.11.1p1-329.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/d3/cvs-1.11.1p1-329.i386.r pm -
SuSE cvs-1.11.1p1-329.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/cvs-1.11.1p1-329. i586.patch.rpm -
SuSE cvs-1.11.1p1-329.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/cvs-1.11.1p1-329. i586.rpm
CVS CVS 1.11.1
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.10
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.11
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.14
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489 -
Mandrake cvs-1.11.14-0.2.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake cvs-1.11.14-0.2.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
SuSE cvs-1.11.14-24.3.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/cvs-1.11.14-24.3. i586.patch.rpm -
SuSE cvs-1.11.14-24.3.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/cvs-1.11.14-24.3. i586.rpm -
SuSE cvs-1.11.14-24.3.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/cvs-1.11.14-2 4.3.x86_64.patch.rpm -
SuSE cvs-1.11.14-24.3.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/cvs-1.11.14-2 4.3.x86_64.rpm
CVS CVS 1.11.15
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.2
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489 -
RedHat cvs-1.11.2-23.legacy.i386.rpm
http://download.fedoralegacy.org/redhat/9/updates/i386/cvs-1.11.2-23.l egacy.i386.rpm -
Slackware cvs-1.11.16-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/c vs-1.11.16-i386-1.tgz
CVS CVS 1.11.3
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.4
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489
CVS CVS 1.11.5
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489 -
Slackware cvs-1.11.16-i386-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/c vs-1.11.16-i386-1.tgz -
SuSE cvs-1.11.5-112.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/cvs-1.11.5-112.i5 86.patch.rpm -
SuSE cvs-1.11.5-112.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/cvs-1.11.5-112.i5 86.rpm
CVS CVS 1.11.6
-
CVS cvs-1.11.16.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=489 -
Slackware cvs-1.11.16-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/c vs-1.11.16-i486-1.tgz -
SuSE cvs-1.11.6-81.i586.patch.rpm
fftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/cvs-1.11.6-81.i5 86.patch.rpm -
SuSE cvs-1.11.6-81.i586.rpm
fftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/cvs-1.11.6-81.i5 86.rpm -
SuSE cvs-1.11.6-81.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/cvs-1.11.6-81 .x86_64.patch.rpm -
SuSE cvs-1.11.6-81.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/cvs-1.11.6-81 .x86_64.rpm
CVS CVS 1.12.1
-
CVS cvs-1.12.8.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=491 -
OpenPKG cvs-1.12.1-1.3.5.src.rpm
ftp://ftp.openpkg.org/release/1.3/UPD/cvs-1.12.1-1.3.5.src.rpm
CVS CVS 1.12.2
-
CVS cvs-1.12.8.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=491
CVS CVS 1.12.5
-
CVS cvs-1.12.8.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=491 -
OpenPKG cvs-1.12.5-2.0.2.src.rpm
ftp://ftp.openpkg.org/release/2.0/UPD/cvs-1.12.5-2.0.2.src.rpm
CVS CVS 1.12.7
-
CVS cvs-1.12.8.tar.gz
http://ccvs.cvshome.org/servlets/ProjectDownloadList?action=download&d lID=491
References
CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability
References:
References:
- Advisory 07/2004 - CVS remote vulnerability (Stefan Esser)
- CVS flag insertion heap exploit (CORE Security)
- CVS Home Page (CVS)
- cvs server buffer overflow vulnerability (Otto Moerbeek
) - RHSA-2004:190-14 - Updated cvs package fixes security issue (RedHat)
- TA04-147A CVS Heap Overflow Vulnerability (US-CERT)